Who we are
KNOC is operated by the team behind the KNOC product (referred to here as "we", "us", or "KNOC"). Our service connects a person who scans a QR code at a door (the "visitor") with the person who owns or manages that door (the "owner").
If you have privacy questions or want to exercise the rights described below, you can reach us at the contact address at the bottom of this page.
What we collect
We try to collect only what the service genuinely needs. There are three categories of data:
- Owner account data: email, name, password (stored as a salted hash, never in plain text), authentication identifiers from Google or Apple if you use social sign-in, profile photo if your social provider supplies one, language and timezone preferences, quiet-hours settings, the doors you create (including any name, address, and location coordinates you set for a door), and your subscription and plan status if you upgrade to a paid plan.
- Visitor submissions and owner replies: anything a visitor chooses to send when they scan a door โ photo, audio recording, text message, phone number โ plus the door they sent it to and an approximate location derived from network signals, together with the owner's replies (text or audio).
- Technical data: IP address (used for approximate location and abuse protection), browser/user-agent string, device push-notification tokens, basic timestamps, and operational logs. When the app or the service runs into an error or crashes, we also collect a diagnostic report describing the failure: the type of error, where in our software it happened, the app version and build, and the device model and operating-system version.
How we use it
We use this data to deliver the doorbell experience: showing the visitor's message to the owner, letting the owner reply, sending push notifications, enforcing service hours and quiet hours, and protecting against abuse.
We do not sell personal information. We do not use visitor submissions to train machine-learning models. We do not share owner contact details with visitors or with each other.
Sensitive data
KNOC collects information that is treated as sensitive personal information under several privacy laws โ for example, audio recordings, photos that include faces, and approximate location. We treat this data with extra care: it is encrypted in transit, scoped to the people who need to see it (the owner of the door it was sent to, and the operations team for support and abuse review), and is automatically removed at the end of the retention window for your plan.
If you live in a jurisdiction that gives you the right to opt out of the "sale" or "sharing" of sensitive information, you can exercise that right by contacting us. We do not sell or share sensitive information for cross-context advertising.
Live audio calls
Some doors offer a live audio call over the internet, an Early Access feature. While a call is connected, microphone audio travels in real time between the visitor's browser and the owner's device.
KNOC does not record or store live-call audio. There is no live-call recording feature and no stored live-call audio file. This is different from voice notes, which a visitor or owner deliberately records and sends, and which we do store โ those are covered under "What we collect" above.
What we keep about a call is metadata: which door and account it belonged to, the identifiers used to route it, when it was requested, rang, was answered and ended, the outcome (answered, declined, missed, expired, and similar), and the ring and length limits that applied. Call metadata is retained separately from visitor submissions and is not subject to the 7-day or 90-day submission window. We use it to operate, secure, troubleshoot, and protect the service from abuse, and may retain it when required by law. We keep short technical logs for the same purposes. We do not keep call content.
To connect a call, the two devices exchange connection details ("signalling") through our realtime service, which passes those messages along and never carries or stores the audio itself. Wherever possible the audio then travels directly between the two devices. Finding that direct path uses a public STUN service operated by Google. If a direct connection cannot be established โ typically behind a restrictive network โ a relay service may forward the encrypted media between participants on our behalf.
On iPhone, an incoming call is delivered through Apple's Push Notification service as a VoIP push, so it can ring even when the app is closed. The push carries limited routing and display information, including call and door identifiers and a caller label built from the visitor's name and door name. Ordinary, non-call notifications are delivered through Firebase Cloud Messaging.
Service providers we share data with
We use a small number of vetted service providers to run the service. They process data only on our behalf and only for the purposes listed:
- Cloud storage: photos, audio, and other large objects are stored on Amazon S3 (AWS). Files are accessed via short-lived signed URLs.
- Push notifications: Firebase Cloud Messaging (Google) delivers ordinary notifications to owner devices, and Apple's Push Notification service delivers the VoIP push that rings an incoming call on iPhone.
- Text messaging: when an owner replies and the visitor opted in, we send a follow-up text via Twilio.
- Billing: subscriptions purchased on the web are processed by Stripe, and purchases made through the App Store are processed by Apple. We never see or store full credit-card numbers.
- Sign-in: Google Sign-In and Sign in with Apple, when an owner chooses one of those options at signup.
- Realtime calling: our realtime service relays connection-setup messages for live audio calls, and a public STUN service operated by Google helps devices find a direct path. Where a direct connection cannot be established, a relay service may forward the encrypted media between participants on our behalf. KNOC does not record or store live-call audio.
- Error and crash diagnostics: we use Sentry to collect reports when the app or the service fails, so we can find and fix the problem. A report describes the failure and the software involved, along with the app version, the device model and operating system, and an identifier for the app installation. We configure it not to send message contents, door names or door links, visitor names, email addresses, phone numbers, sign-in tokens, or Apple sign-in identifiers, and we have turned off IP-address storage and the approximate location that would otherwise be derived from it. We use diagnostic data only to keep KNOC working โ never for advertising, and never to track you across other apps or websites.
How long we keep data
Visitor submissions are kept for a window that depends on the door owner's plan: seven days on the free tier, ninety days on paid plans. The window is set when the knock arrives, so changing plans doesn't extend or shorten knocks that already exist. When the window ends, a daily job deletes the submission along with its photo and audio files.
Call records are not part of this window; they are kept as described under "Live audio calls" above. Records we keep to investigate abuse and protect the security of the service are also kept separately from this window, for those purposes.
We may retain specific records longer when required by applicable law, or for short fraud-prevention purposes.
When you delete your owner account, we deactivate it immediately and schedule it for permanent deletion after a 30-day grace period. Deletion runs automatically after that point, but it is not instantaneous: it may be delayed while we complete billing reconciliation, retry a step that failed, preserve records needed for an abuse or security investigation, or retain a specific record the law requires us to keep.
Your rights
Depending on where you live, you may have the right to: access the personal information we hold about you, correct inaccurate data, delete your data, restrict or object to certain processing, receive a portable copy of your data, and opt out of any "sale" or "sharing" of your information (we do not engage in either).
Owners can exercise most of these rights directly inside the app โ the Settings page lets you update your details, change your preferences, and schedule the deletion of your account. Visitors can request the same rights by contacting us with the door slug and an approximate timestamp of their submission so we can find the right record.
Children
KNOC is not directed at children. We do not knowingly collect personal information from children under 13 (or the equivalent age in your country). If you believe a child has submitted personal information through KNOC, please contact us and we will delete the record.
International data transfers
Depending on your country and the cloud regions our service providers use, your data may be processed in a country other than your own. Where required by local law, we use contractual safeguards to protect data during these transfers.
How we protect your data
We use industry-standard practices: encryption in transit, encryption at rest where supported by our storage providers, scoped access controls inside the app, short-lived signed URLs for media files, and operational monitoring. No system is perfectly secure, and we will notify affected users in line with applicable law if a breach poses a real risk to them.
Changes to this policy
We may update this policy as the service evolves or as the law changes. The "Last updated" date at the bottom of this page reflects the most recent revision. Material changes will be highlighted on the homepage or in the app for a reasonable period before they take effect.
Contact
You can contact us about privacy at hello@knoc.app. Please include enough detail for us to identify your record (for owners: the email tied to your account; for visitors: the door slug and an approximate timestamp).